Resultant Set of Policy

When you use fine-grained password policies, some objects may have multiple fine-grained password policies applied. However, only one password policy can be applied to an object. It is not possible to merge multiple policies either.

Resultant Set of Policy (RSoP) uses the attribute value of msDS-PasswordSettingsPrecedence, which is associated with each password to decide winning policy. A precedence value is an integer value that the administrator can define. A lower precedence value means higher priority. If multiple password policies are applied to the same object, the password policy with the lower precedence value wins.

Following list further explain how password policies works in an infrastructure:

  • There are two ways in which an object can be linked to a password policy. The first method is via a directly linked policy. The second method is via group membership. If the policy targets a security group, its members will automatically have the password policy inherited. However, if a fine-grained password policy is linked to an object directly, it will be the winning policy.
  • If there's no directly linked policy, object will consider the lowest policy precedence. These policies are inherited from its security groups.
  • If both the settings are not applicable, the default GPO password policy setting is applied.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.144.84.155